Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-26149
HistoryFeb 26, 2024 - 8:19 p.m.

Design/Logic Flaw

2024-02-2620:19:00
PRIOn knowledge base
www.prio-n.com
3
vyper
smart contract
language
vulnerability
_abi_decode
array index
overflow
exploitation

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%

Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an excessively large value is specified as the starting index for an array in _abi_decode, it can cause the read position to overflow. This results in the decoding of values outside the intended array bounds, potentially leading to exploitations in contracts that use arrays within _abi_decode. This vulnerability affects 0.3.10 and earlier versions.

6.9 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%

Related for PRION:CVE-2024-26149